Last updated: August 4, 2026— this is a first draft, not yet reviewed by a lawyer.
Who we are
The Lab is operated by Tutor Labs Canada Inc., 6949 Courtright Line, Alvinston, Ontario, N0N 1A0. This policy explains what personal information we collect from students, parents, tutors, and school partners, and how we use it.
This service is used by minors
Most students on The Lab are in grades 7-12 and may be under 18, and some are under 13. We've written this policy with that in mind, and we collect the minimum information needed to run tutoring sessions, quizzes, and the Lab Assistant AI Tutor. If you're a parent or guardian with questions or concerns about your child's account, contact us at admin@tutorlabscanada.com and we'll respond directly.
What we collect
- Account information: name, email, password (stored securely by our authentication provider, never in plain text), grade, and province.
- Tutoring activity:session bookings, attendance, homework files and class notes you or your tutor upload, and messages sent in a session's live chat.
- Lab Assistant AI Tutor conversations: the messages you send the AI tutor and its replies, stored so your conversation history works across visits. See the AI Features section below for how these are handled.
- Learning activity: quiz attempts and scores, badges earned, and daily activity used to track streaks.
- Payment information: subscription and per-session billing is processed by Stripe. We never see or store your full card number - Stripe handles that directly.
- Device information: if you turn on push notifications, we store a device token so we can send them; nothing else about your device is collected.
How we use it
To run the platform: matching you with tutors, scheduling and billing sessions, grading quizzes, awarding badges, sending reminders, and responding to your messages to the Lab Assistant. We don't sell personal information, and we don't use it for advertising - The Lab doesn't run ads and has no third-party analytics or tracking scripts.
Who we share it with
- Supabase hosts our database, authentication, and file storage.
- Stripe processes payments and stores payment method details.
- Anthropicprovides the Claude AI model that powers the Lab Assistant AI Tutor - your messages to it are sent to Anthropic's API to generate a response.
- Resend delivers transactional emails (reminders, receipts, notifications).
We don't share information with anyone else, and never sell it.
AI features
The Lab Assistant AI Tutor is an AI system, not a person - see the notice shown on that page. Conversations with it are not used by Anthropic to train its models by default; the only way that would change is a deliberate account-level setting we have confirmed is off. If something you write to the Lab Assistant suggests you might be in crisis or unsafe, an automated check flags it for a staff member at The Lab to review - this is about your safety, not moderation of ordinary conversations, and most conversations are never reviewed by a person.
For the full risk analysis - what could go wrong with these AI features, what we've built to catch it, and testing results - see our Algorithmic Impact Assessment.
Children's privacy & safety
Here's what we actually do today to keep student accounts safe, in plain terms - not a claim that this is complete or that we run any formal outside audit of it, just an honest account of the measures in place:
- Age and consent:we ask for a date of birth at signup. For a student under 13, we don't let them use the platform until a parent or guardian confirms consent by email.
- Wellbeing monitoring: every message a student sends the Lab Assistant is checked for signs of crisis, self-harm, or a disclosure of abuse, assault, depression, or anxiety. A match flags the message for a staff member to review and immediately notifies them by email and in-app notification - it never blocks or changes the conversation itself.
- Chat content filtering: messages in a live tutoring session are checked for profanity, attempts to move the conversation off-platform, sexual content, or grooming-pattern language, and flagged for staff review the same way.
- Uploaded images:we don't currently run automated scanning on photos uploaded to the Lab Assistant or homework uploads. If a staff member becomes aware of an image that may depict child sexual abuse material, our process is to report it directly to Cybertip.ca, Canada's tipline for reporting the online sexual exploitation of children, rather than attempt to handle it internally.
- Data minimization: we collect the information needed to run tutoring, quizzes, and the Lab Assistant, nothing more - see What we collect above.
If you have a concern about a student's safety on The Lab, email admin@tutorlabscanada.com directly and we'll treat it as a priority.
Your rights and choices
You can review and update your profile information any time in Settings. You can delete your account and all associated personal data yourself from Settings as well - this happens right away, not on some later schedule. Two things can affect that: if your account has an active legal hold (see below), we can't delete it until the hold is released and we'll tell you why; and a few records - tax and payment records (7 years) and our internal breach register (24 months) - survive on purpose because the law requires us to keep them. See How long we keep data below for the full list of what's kept and why. If you'd rather we do it for you, or you have any other request about your data, email admin@tutorlabscanada.com.
How long we keep data
We're publishing our full, itemized data retention schedule here as we finish building it, category by category. This section currently covers accounts/identity data, QuizLab, badges/progress, Tutor Labs Classroom, file uploads, communications, the Lab Assistant AI Tutor, safety & moderation, money, schools, tutors & staff, technical infrastructure, backups, compliance recordkeeping, and the overrides (legal holds, deletion requests, and legal minimums) that apply across all of it - this is now the complete schedule.
- Profile and login data- deleted immediately from our live database when you delete your account, whether you do it yourself or ask us to. Because we keep rolling backups (see Backups below), a copy can still exist in a backup for up to 30 days afterward, until that backup rolls off - after that, it's completely gone.
- Unconfirmed sign-ups - if you create an account but never confirm your email, we delete it automatically after 30 days.
- Inactive accounts- if a student account has no activity and no active subscription for 18 months, we delete it automatically, with a warning email one month, one week, and one day before deletion so it's always a choice, not a surprise.
- Consent records- we keep a record of when you accepted our Terms of Service and Privacy Policy. This record is kept for 24 months after your account is deleted, so we can demonstrate we had your consent for anyone who has since left - after that it's purged too.
- Deletion record - when an account is deleted, we keep a one-way cryptographic hash of the email address (never the address itself) indefinitely, so we can prove someone was deleted and avoid accidentally re-adding them through a bulk import.
- QuizLab attempts and answers - your individual quiz attempts, per-question answers, and any responses flagged for review are kept for 300 days after you submit them (roughly a semester plus exam period), then deleted. Anonymised scores and completion rates, with no link back to your account, are kept indefinitely so we can see which topics need better content.
- Quiz content- quizzes and questions written by tutors, including any images used in a question, are kept indefinitely while they're in use, since they're teaching material, not personal information. If the tutor who wrote them later deletes their account, the content stays; only the internal attribution to that account is cleared. Deleting a question deletes its images with it.
- Badges and streaks- the badges you've earned and your current/longest streak are kept for as long as you're a student here, and removed entirely when your account is deleted - nothing survives, on purpose. That's exactly why account deletion warns you first.
- Daily activity and streak-loss records - the individual record of which days you were active, and of each time a streak broke, is kept for 400 days (a year plus a comparison buffer) then deleted. Anonymised daily active-user counts and streak-length counts, with no link back to your account, are kept indefinitely.
- Event week participation - the badge you earn for taking part in a limited-time event week is removed with the rest of your badges if your account is deleted. An anonymised count of how many students took part in each event is kept indefinitely.
- Classroom bookings - the subject, grade, date, tutor, attendance, and cancellation record of a session is kept for 24 months after the session date, then deleted. Anonymised counts of sessions and cancellations by subject and grade, with no link back to any student or tutor, are kept indefinitely.
- Recurring series- a recurring booking series is kept for 24 months after it's cancelled or ends, so the individual sessions it generated still make sense, then deleted.
- Reschedule offers, group invitations, and tutor decline history - this operational detail follows the booking it's attached to and is deleted on the same 24-month clock.
- Outside-availability requests - if you ask for a subject we don't currently have a tutor for, that request is kept for 12 months. If a tutor becomes available and takes it on, it becomes a normal booking and follows the 24-month booking clock instead. An anonymised count of demand by subject, grade, and province is kept indefinitely.
- Per-session billing records - unlike the booking itself, what you were charged for a session is a financial record, not a booking record. It's kept for 7 years to meet our tax obligations, and survives both the booking-deletion job above and your own account deletion.
- Homework files - a photo or PDF you upload for a session is deleted, file and record together, 30 days after you upload it. Nothing is kept past that point.
- Class notes- the notes a tutor uploads for a session are deleted, file and record together, 300 days after upload. We also run a weekly check for any uploaded file that should have already been deleted but wasn't fully cleaned up, so nothing lingers by mistake.
- Technical-issues session chat - messages in a live tutoring session's chat are kept for 120 days after they're sent, then deleted. If a message was ever flagged by our automated safety check (see Children's privacy & safety above), the flag record - including a copy of the message itself, plus the few messages immediately before it for context - is kept separately as a safety record for 24 months from when the flag was raised, then deleted too.
- In-app notifications- the reminders and alerts you get in the app are kept for 12 months after they're created, then deleted.
- Feedback you submit - a complaint, suggestion, or other feedback you send us is kept for 24 months, then deleted. An anonymised count of feedback by category, with no link back to your account, is kept indefinitely so we can see what comes up most.
- Email delivery logs- we don't keep our own copy of when an email was delivered, opened, or bounced. That log lives with Resend, the service we use to send email, under their own retention settings (typically around 30 days).
- Lab Assistant conversation content - what you and the Lab Assistant actually typed is deleted 14 days after you send it, whether the conversation ended, went quiet, or you deleted it yourself. If a message was ever flagged by our automated wellbeing check (see Children's privacy & safety above), the flag keeps its own copy of that message, the few messages just before it, and the Lab Assistant's reply, as a safety record, kept separately and not deleted on this schedule.
- Lab Assistant usage counters - how many messages you sent and roughly what a session cost us (not the words themselves) are kept for 400 days, since some of our badges are earned by using the Lab Assistant a certain amount. After that, only an anonymised monthly total across all students is kept, indefinitely.
- Lab Assistant weekly usage - a running record of how much you've used the Lab Assistant each week is kept for 13 months, so we can show you your own usage history and, in the future, manage fair usage across all students. An anonymised monthly total is kept indefinitely after that.
- Opted-in conversations for AI training - you can opt in, in Settings, to help us improve how the Lab Assistant teaches. If you do, future conversations are kept in full for 12 months from when each one is saved, instead of the usual 14 days, specifically so we can review real conversations and revise the AI's teaching approach. Nothing is kept if you don't opt in, and you can opt out at any time.
- Peer review submissions - a draft you submit for peer review is deleted 14 days after submission, with nothing kept. The surrounding conversation (the outline discussion and the review reply) follows the same 14-day schedule as regular Lab Assistant conversations, described above.
- What the AI provider keeps - beyond our own database, Anthropic (who provides the Claude model powering the Lab Assistant) keeps its own copy of each API call under their own retention policy, separate from ours.
- Safeguarding incident reports - if a serious safety concern is formally reported and investigated, we keep a record of the report and its outcome for at least 24 months after it's resolved (this floor may be raised on legal advice). These records are reviewed and purged manually, never on an automatic schedule.
- Tutor cancellation and schedule-action history - a tutor's record of declined or cancelled sessions, and the late-cancellation count derived from it, is kept while they're active with us and for 24 months after their engagement ends, then cleared. Nothing survives past that.
- Legal holds- if an account's records become relevant to actual or anticipated legal proceedings, we can place a hold that exempts everything tied to it from every deletion or purge on this page - automatic, or requested by you - until the hold is released. If you ask us to delete an account under an active hold, the deletion is blocked and you're told why, not left wondering.
- Subscriptions, invoices, receipts, per-session charges, and referral rewards - these are financial records, and Canadian tax law requires us to keep them for 7 years from the transaction date. This is not something we can change on request - it survives account deletion and every other purge on this page, and is never automatically removed.
- Saved card reference - we never see or store your actual card number; what we hold is a token from our payment processor, Stripe. When you remove your card or delete your account, that token is revoked at Stripe immediately and cleared from our database. You can't remove your card or delete your account while you have an upcoming Classroom session scheduled - cancel it first.
- Payment processor records - Stripe keeps its own copy of every transaction under its own retention policy, driven by financial regulation. We can't delete those records or promise a timeline for them - they're outside our control.
- School pricing enquiry leads - if you (or your school) fill out our "Request pricing" form, we keep that contact information for 24 months from the last time we touched it. If nothing comes of it and 24 months of silence pass, it's deleted automatically; nothing is kept.
- School contracts, seats, and invoices - once a school signs a contract with us, the contract terms, seat count, and invoices are commercial and tax records, kept for 7 years after the contract ends. This is a manual process, not automatic, and survives the contract's own expiry.
- School domain verification - the DNS record we use to auto-enroll students on a school's verified email domain is an access control, not a financial record. Unlike the contract and invoice records above, it's deleted automatically the moment the contract ends.
- Aggregate school usage reporting - we keep a daily snapshot of seat usage and revenue per school so we can show year-over-year numbers at renewal time. These aggregates never contain individual student work, and are kept until 12 months after that school's contract ends.
- Tutor profile, subjects, and pay rate - a tutor's profile, the subjects/grades they're assigned to teach, and their pay rate are contractor and tax records, kept for 7 years after their engagement with us ends. This is a manual process, not automatic.
- Vulnerable sector check - we record only the date of the check and its pass/fail outcome, never the police report itself. Kept for 7 years after engagement ends alongside the rest of the tutor's record; the date and outcome alone (with no link back to the tutor) are kept indefinitely after that for our own compliance history.
- Time off requests- the dates and stated reason for a tutor's time off request are kept for 24 months after we've made a decision on it, then deleted automatically.
- Availability schedule- a tutor's weekly availability is cleared the moment their engagement with us ends. Nothing is kept.
- Tutor invite links- an invite link to join as a tutor stops working 14 days after it's sent, and the record is deleted entirely 90 days after being sent.
- Signed policy acknowledgements & training records - documents showing a tutor was trained and agreed to our code of conduct are kept for 7 years after their engagement ends, as our own evidence of what we required of them. This is a manual process, not automatic.
- Sign-in and authentication logs - Supabase, our authentication provider, keeps its own record of sign-in events (separate from your profile) for 90 days - enough to investigate a suspicious login, not enough to build a picture of your movements over time. This is a setting on Supabase's side, not something stored in our own database.
- Error reports- we don't currently use a third-party error-monitoring tool. If we ever do, error reports will be scrubbed of personal information before being sent, kept for 30-90 days, then deleted automatically under that provider's own settings.
- Product analytics- as stated above, we don't run any third-party analytics or tracking scripts today. If that ever changes, events would be tied only to an internal account number, never your name, email, or content, would never run on a page you're viewing while signed in as a student, and would be kept for 24 months, after which only anonymised aggregates - with no link back to any account - would be kept.
- Application and access logs - Vercel, our hosting provider, keeps its own short-lived request and access logs (around 30 days) under its own retention settings. We don't keep a separate copy.
- Workshop recordings- Workshops are recorded, but the recording is never hosted on our own platform - it stays in the tutor's Zoom account, and everyone who attended gets a link directly from Zoom to rewatch it for up to 14 days after the session, after which it's deleted. By signing up for a Workshop, you're agreeing to be recorded on this basis. One-on-one and group tutoring sessions are never recorded, unless we tell you otherwise for a specific session.
- Backups- Supabase, our database host, keeps rolling daily backups on a 7-day cycle under our Pro plan. If data is deleted from our live database, it can still exist in one of these backups until that backup rolls off - within 30 days at the outside. This is a setting on Supabase's side, not something we manage or extend ourselves.
- Compliance recordkeeping- separately from the data described above, we maintain a small set of internal records to demonstrate we're following this policy: a register of any data breach we discover, however minor (kept 24 months from discovery); a log of access, correction, and deletion requests and how we responded (kept 24 months from when a request is closed); and dated copies of the terms and data processing agreements we accept from vendors who handle your data (kept for as long as we use that vendor, plus 7 years after). We also keep a record of when and why this retention schedule itself changes, reviewed annually. These records are kept internally, are never sold or shared, and don't contain more personal information than the data they're documenting already required.
Changes to this policy
If we make a material change to this policy, we'll post the update here and update the date at the top of the page.